Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

81–90 of 287 posts

Re: Coinbase Breach Notification

#82

Earlier quoted context omitted.

Agree. Although I would like coinbase to move away from SMS 2fa

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

[deleted]

Re: Coinbase Breach Notification

#83
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

Many cryptocurrencies are deflationary and/or have fixed supply; I cannot say the same for the dollars in my bank account. https://fred.stlouisfed.org/series/MABMM301USM189S

That's why you don't store money in your bank account, you keep it in investment vehicles which also appreciate in value over the long run (not the best inflation foil, but an OK one)

Re: Coinbase Breach Notification

#84

Earlier quoted context omitted.

Agree. Although I would like coinbase to move away from SMS 2fa

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

I'm not entirely familiar with coinbase, so is it really 2fa or is it 1fa in that you can use SMS as a recovery method when you don't know your password?

Re: Coinbase Breach Notification

#85
post #48
post #16

Earlier quoted context omitted.

Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.

> everyone should walk happy. The reimbursement comes from somewhere. Investors may not be happy. "everything is securities fraud" https://www.google.com/search?q=%22everything+is+securities+...

I'm guessing their insurance didn't cover it since it related to insecure account practices. So this is likely from their own revenues.

https://help.coinbase.com/en/coinbase/other-topics/legal-pol...

I don't see the connection with your link to securities fraud though.

Re: Coinbase Breach Notification

#86
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…

The benefits of the banking system I would propose to be self-explanatory, though your parent comment recaps them well.

It's the reason to do the crypto part at all that's more confusing. Unless of course we all just admit that gambling is unbelievably popular and fun and has been a continued hit throughout human history.

Re: Coinbase Breach Notification

#87
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

Many cryptocurrencies are deflationary and/or have fixed supply; I cannot say the same for the dollars in my bank account. https://fred.stlouisfed.org/series/MABMM301USM189S

> Many

> fixed supply

Perhaps we've identified a small crack in this otherwise bulletproof logic.

Re: Coinbase Breach Notification

#88
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

They would not be required to have all that info for an attacker to steal if it was not for the ridiculous reporting and KYC laws of the US

Re: Coinbase Breach Notification

#90
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

This seems like an egregious use of the word "literally" I think you should look up the use cases for decentralized finance.

There are two spectacular use cases: gambling and illicit transactions

That's not snark, those are great use cases, both have thousands of years of popularity behind them and tons of demand.

Hence my parent comment, which points out that when you use the more heavily regulated centralized exchanges like coinbase the one remaining use case is gambling.

Post reply on HN